{"id":21394,"date":"2017-05-19T10:30:36","date_gmt":"2017-05-19T10:30:36","guid":{"rendered":"https:\/\/one.sightlinemg.com\/c4isrnet\/uncategorized\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/"},"modified":"2026-08-08T18:08:24","modified_gmt":"2026-08-08T18:08:24","slug":"should-spies-use-secret-software-vulnerabilities-commentary","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/","title":{"rendered":"Should spies use secret software vulnerabilities? [Commentary]"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The recent WannaCry ransomware attack <\/p>\n\n\n\n<a href=\"http:\/\/www.cbsnews.com\/news\/cyberattack-wannacry-ransomware-north-korea-hackers-lazarus-group\/\" rel=\"noopener noreferrer\" target=\"_blank\">infected about 300,000 computers in 150 countries<\/a>\n\n\n\n<p class=\"wp-block-paragraph\">, and cost computer users <\/p>\n\n\n\n<a href=\"http:\/\/www.nbcnews.com\/tech\/security\/total-paid-malware-ransom-how-exploit-spread-n759531\" rel=\"noopener noreferrer\" target=\"_blank\">thousands of dollars in ransom money<\/a>\n\n\n\n<p class=\"wp-block-paragraph\"> and <\/p>\n\n\n\n<a href=\"http:\/\/www.cbsnews.com\/news\/wannacry-ransomware-attacks-wannacry-virus-losses\/\" rel=\"noopener noreferrer\" target=\"_blank\">billions in lost productivity<\/a>\n\n\n\n<p class=\"wp-block-paragraph\">.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The attack took advantage of a vulnerability in the Windows operating system that the federal government had been aware of for years but had chosen not to tell Microsoft about until just months before the WannaCry attack began. That history and the potential for <a href=\"https:\/\/www.engadget.com\/2017\/05\/16\/shadow-brokers-nsa-june\/\" rel=\"noopener noreferrer\" target=\"_blank\">more releases in the coming weeks<\/a> have intensified the debate around how governments and spy agencies should act when they discover weaknesses in computer software.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It&#8217;s a choice of how best to protect the public: <a href=\"https:\/\/www.washingtonpost.com\/business\/technology\/nsa-officials-worried-about-the-day-its-potent-hacking-tool-would-get-loose-then-it-did\/2017\/05\/16\/50670b16-3978-11e7-a058-ddbb23c75d82_story.html\" rel=\"noopener noreferrer\" target=\"_blank\">Exploit software vulnerabilities to collect intelligence information<\/a> that may help keep people safe? Or disclose the flaw, letting the software company fix it and <a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2017\/05\/14\/need-urgent-collective-action-keep-people-safe-online-lessons-last-weeks-cyberattack\/\" rel=\"noopener noreferrer\" target=\"_blank\">protect millions of regular computer users from malicious attacks<\/a> by hackers?\n<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Exposing WannaCry<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For years, <a href=\"https:\/\/www.washingtonpost.com\/business\/technology\/nsa-officials-worried-about-the-day-its-potent-hacking-tool-would-get-loose-then-it-did\/2017\/05\/16\/50670b16-3978-11e7-a058-ddbb23c75d82_story.html\" rel=\"noopener noreferrer\" target=\"_blank\">the U.S. National Security Agency used a flaw in the Windows operating system<\/a>, nicknamed &#8220;EternalBlue,&#8221; to spy on intelligence targets, gathering information from their computer files and electronic communications. But the NSA didn&#8217;t tell Microsoft about the flaw in the company&#8217;s software until early 2017. The company <a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms17-010.aspx\" rel=\"noopener noreferrer\" target=\"_blank\">quickly issued a fix<\/a> users could download and install. <a href=\"https:\/\/theconversation.com\/why-installing-software-updates-makes-us-wannacry-77667\" rel=\"noopener noreferrer\" target=\"_blank\">Many people didn&#8217;t<\/a>, though.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In April, a hacking group called the <a href=\"https:\/\/www.engadget.com\/2017\/04\/14\/shadow-brokers-dump-windows-zero-day\/\" rel=\"noopener noreferrer\" target=\"_blank\">Shadow Brokers reported that it had breached the network<\/a> of, and stolen information from, computers used by the Equation Group, which has not identified itself but is <a href=\"http:\/\/www.reuters.com\/article\/us-usa-cyberspying-idUSKBN0LK1QV20150216\" rel=\"noopener noreferrer\" target=\"_blank\">widely believed to be part of the NSA<\/a>. The Shadow Brokers revealed <a href=\"https:\/\/theconversation.com\/after-the-nsa-hack-cybersecurity-in-an-even-more-vulnerable-world-64090\" rel=\"noopener noreferrer\" target=\"_blank\">information about extremely sophisticated digital tools<\/a> for attacking military, political and economic targets worldwide. One of those tools was &#8220;EternalBlue.&#8221;\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In May, a hacker or hacking group released a piece of malicious software using &#8220;EternalBlue&#8221; to hijack computers, encrypt the data on them and charge victims a ransom to restore access to their information.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the NSA had told Microsoft about the flaw five years ago, things could have unfolded differently. In particular, users could have had much more time to update their software \u2013 which would have <a href=\"https:\/\/theconversation.com\/why-installing-software-updates-makes-us-wannacry-77667\" rel=\"noopener noreferrer\" target=\"_blank\">substantially increased the number of people protected<\/a> against the vulnerability.\n<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Using \u0091zero days\u0092<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The most serious cyberattacks are those that use previously unknown vulnerabilities. They are called &#8220;zero day&#8221; exploits because the developers had no time to fix it before trouble began, and nobody is protected. The NSA may know of <a href=\"https:\/\/jia.sipa.columbia.edu\/online-articles\/healey_vulnerability_equities_process\" rel=\"noopener noreferrer\" target=\"_blank\">hundreds, or even thousands, of them<\/a>. Spy agencies of other countries, including <a href=\"https:\/\/www.nytimes.com\/2014\/04\/13\/us\/politics\/obama-lets-nsa-exploit-some-internet-flaws-officials-say.html?_r=1\" rel=\"noopener noreferrer\" target=\"_blank\">China, Russia, Iran and North Korea<\/a>, are also working to find zero-day vulnerabilities.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Using these vulnerabilities can be effective. For instance, the NSA used four zero-day vulnerabilities as part of a series of cyberattacks on Iran&#8217;s nuclear enrichment sites. That effort, officially code-named &#8220;Olympic Games,&#8221; created the program known to the public as &#8220;<a href=\"https:\/\/www.wired.com\/2014\/11\/countdown-to-zero-day-stuxnet\/\" rel=\"noopener noreferrer\" target=\"_blank\">Stuxnet<\/a>,&#8221; which damaged about 1,000 centrifuges and <a href=\"https:\/\/www.nytimes.com\/2014\/04\/13\/us\/politics\/obama-lets-nsa-exploit-some-internet-flaws-officials-say.html?_r=1\" rel=\"noopener noreferrer\" target=\"_blank\">may have helped force Iran to negotiate<\/a> with the U.S. about its nuclear program.\n<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Should they keep the secret?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">By not telling software companies about newly identified vulnerabilities, government agencies such as the NSA and CIA serve their own purposes of finding ways to gather intelligence undetected. But they also <a href=\"https:\/\/fcw.com\/articles\/2017\/03\/13\/zero-day-stockpile-carberry.aspx\" rel=\"noopener noreferrer\" target=\"_blank\">endanger critical systems of governments and regular users alike<\/a>.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The U.S. does not have strong and clear policies with which to handle this problem. In January 2014, the <a href=\"https:\/\/jia.sipa.columbia.edu\/online-articles\/healey_vulnerability_equities_process\" rel=\"noopener noreferrer\" target=\"_blank\">Obama administration ordered spy agencies<\/a> to <a href=\"https:\/\/www.wired.com\/2014\/04\/obama-zero-day\/\" rel=\"noopener noreferrer\" target=\"_blank\">disclose weaknesses they find<\/a> \u2013 but with a significant loophole: If a software flaw has &#8220;a clear national security or law enforcement&#8221; use, the government can <a href=\"http:\/\/www.reuters.com\/article\/us-apple-encryption-review-idUSKCN0WW2OL\" rel=\"noopener noreferrer\" target=\"_blank\">keep the flaw secret<\/a> and exploit it.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These are <a href=\"http:\/\/dx.doi.org\/10.1080\/01972243.2016.1177764\" rel=\"noopener noreferrer\" target=\"_blank\">complex trade-offs<\/a> involving many questions: What might spies learn by exploiting the vulnerability? How likely is it that adversaries could find it? What might happen if they use it? <a href=\"https:\/\/www.wired.com\/2017\/05\/governments-wont-let-go-secret-software-bugs\/\" rel=\"noopener noreferrer\" target=\"_blank\">Can the secret be kept securely and reliably<\/a>? Regardless of the <a href=\"http:\/\/dx.doi.org\/10.1145\/2535813.2535818\" rel=\"noopener noreferrer\" target=\"_blank\">ethics questions<\/a> about how these agencies should best carry out their duty of protecting the public, the decision will likely end up as a political one, about <a href=\"https:\/\/jia.sipa.columbia.edu\/online-articles\/healey_vulnerability_equities_process\" rel=\"noopener noreferrer\" target=\"_blank\">how the government should use its power<\/a>.\n<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><a href=\"http:\/\/theconversation.com\/should-spies-use-secret-software-vulnerabilities-77770\" rel=\"noopener noreferrer\" target=\"_blank\">This article was originally published on The Conversation.<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It\u0092s a choice of how best to protect the public: Exploit software vulnerabilities to collect intelligence information that may help keep people safe? Or disclose the flaw, letting the software company fix it and protect millions of regular computer users from malicious attacks by hackers?<\/p>\n","protected":false},"author":7,"featured_media":63112,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":29,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":{"8":{"categories":[],"primary_category":""}}},"categories":[106,29,32,24],"tags":[],"coauthors":[2464],"class_list":["post-21394","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-daily-brief","category-home","category-newsletters","category-opinion"],"acf":{"subheadline":"","legacy_arc_id":"S6EMFL4QVJEZLMMXWKKRSYTKVQ","arc_canonical_url":"\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Should spies use secret software vulnerabilities? [Commentary] - C4ISRNet<\/title>\n<meta name=\"description\" content=\"It\u0092s a choice of how best to protect the public: Exploit software vulnerabilities to collect intelligence information that may help keep people safe? Or disclose the flaw, letting the software company fix it and protect millions of regular computer users from malicious attacks by hackers?\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Should spies use secret software vulnerabilities? [Commentary]\" \/>\n<meta property=\"og:description\" content=\"It\u0092s a choice of how best to protect the public: Exploit software vulnerabilities to collect intelligence information that may help keep people safe? Or disclose the flaw, letting the software company fix it and protect millions of regular computer users from malicious attacks by hackers?\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/\" \/>\n<meta property=\"og:site_name\" content=\"C4ISRNet\" \/>\n<meta property=\"article:published_time\" content=\"2017-05-19T10:30:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T18:08:24+00:00\" \/>\n<meta name=\"author\" content=\"Aaron Boyd\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Aaron Boyd\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2017\\\/05\\\/19\\\/should-spies-use-secret-software-vulnerabilities-commentary\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2017\\\/05\\\/19\\\/should-spies-use-secret-software-vulnerabilities-commentary\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"Should spies use secret software vulnerabilities? [Commentary]\",\n\t            \"datePublished\": \"2017-05-19T10:30:36+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:08:24+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2017\\\/05\\\/19\\\/should-spies-use-secret-software-vulnerabilities-commentary\\\/\"\n\t            },\n\t            \"wordCount\": 671,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2017\\\/05\\\/19\\\/should-spies-use-secret-software-vulnerabilities-commentary\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/file-20170518-12257-625y70.jpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Daily Brief\",\n\t                \"Home\",\n\t                \"Newsletters\",\n\t                \"Opinion\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2017\\\/05\\\/19\\\/should-spies-use-secret-software-vulnerabilities-commentary\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2017\\\/05\\\/19\\\/should-spies-use-secret-software-vulnerabilities-commentary\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2017\\\/05\\\/19\\\/should-spies-use-secret-software-vulnerabilities-commentary\\\/\",\n\t            \"name\": \"Should spies use secret software vulnerabilities? [Commentary] - C4ISRNet\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2017\\\/05\\\/19\\\/should-spies-use-secret-software-vulnerabilities-commentary\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2017\\\/05\\\/19\\\/should-spies-use-secret-software-vulnerabilities-commentary\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/file-20170518-12257-625y70.jpg.jpg\",\n\t            \"datePublished\": \"2017-05-19T10:30:36+00:00\",\n\t            \"dateModified\": \"2026-08-08T18:08:24+00:00\",\n\t            \"description\": \"It\u0092s a choice of how best to protect the public: Exploit software vulnerabilities to collect intelligence information that may help keep people safe? Or disclose the flaw, letting the software company fix it and protect millions of regular computer users from malicious attacks by hackers?\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2017\\\/05\\\/19\\\/should-spies-use-secret-software-vulnerabilities-commentary\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2017\\\/05\\\/19\\\/should-spies-use-secret-software-vulnerabilities-commentary\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2017\\\/05\\\/19\\\/should-spies-use-secret-software-vulnerabilities-commentary\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/file-20170518-12257-625y70.jpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/file-20170518-12257-625y70.jpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/2017\\\/05\\\/19\\\/should-spies-use-secret-software-vulnerabilities-commentary\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/home\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"Should spies use secret software vulnerabilities? [Commentary]\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"description\": \"Media for the Intelligence-Age Military | C4ISRNET\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"caption\": \"C4ISRNet\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Should spies use secret software vulnerabilities? [Commentary] - C4ISRNet","description":"It\u0092s a choice of how best to protect the public: Exploit software vulnerabilities to collect intelligence information that may help keep people safe? Or disclose the flaw, letting the software company fix it and protect millions of regular computer users from malicious attacks by hackers?","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/","og_locale":"en_US","og_type":"article","og_title":"Should spies use secret software vulnerabilities? [Commentary]","og_description":"It\u0092s a choice of how best to protect the public: Exploit software vulnerabilities to collect intelligence information that may help keep people safe? Or disclose the flaw, letting the software company fix it and protect millions of regular computer users from malicious attacks by hackers?","og_url":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/","og_site_name":"C4ISRNet","article_published_time":"2017-05-19T10:30:36+00:00","article_modified_time":"2026-08-08T18:08:24+00:00","author":"Aaron Boyd","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Aaron Boyd","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"Should spies use secret software vulnerabilities? [Commentary]","datePublished":"2017-05-19T10:30:36+00:00","dateModified":"2026-08-08T18:08:24+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/"},"wordCount":671,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/file-20170518-12257-625y70.jpg.jpg","articleSection":["Daily Brief","Home","Newsletters","Opinion"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/","name":"Should spies use secret software vulnerabilities? [Commentary] - C4ISRNet","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/file-20170518-12257-625y70.jpg.jpg","datePublished":"2017-05-19T10:30:36+00:00","dateModified":"2026-08-08T18:08:24+00:00","description":"It\u0092s a choice of how best to protect the public: Exploit software vulnerabilities to collect intelligence information that may help keep people safe? Or disclose the flaw, letting the software company fix it and protect millions of regular computer users from malicious attacks by hackers?","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/file-20170518-12257-625y70.jpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/file-20170518-12257-625y70.jpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/2017\/05\/19\/should-spies-use-secret-software-vulnerabilities-commentary\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/c4isrnet\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Home","item":"https:\/\/one.sightlinemg.com\/c4isrnet\/home\/","ad_zone":"home"},{"@type":"ListItem","position":3,"name":"Should spies use secret software vulnerabilities? [Commentary]"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#website","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/","name":"C4ISRNet","description":"Media for the Intelligence-Age Military | C4ISRNET","publisher":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/c4isrnet\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization","name":"C4ISRNet","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","caption":"C4ISRNet"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/c4isrnet\/author\/migration\/"}]}},"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/file-20170518-12257-625y70.jpg.jpg","jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"C4ISRNet","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/c4isrnet","push-errors":false,"_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/21394","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/comments?post=21394"}],"version-history":[{"count":1,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/21394\/revisions"}],"predecessor-version":[{"id":21401,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/21394\/revisions\/21401"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/media?parent=21394"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/categories?post=21394"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/tags?post=21394"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/coauthors?post=21394"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}